What is it about?
Security scanners can identify weaknesses in web applications, but their reports can be difficult to understand and act on. We developed SafeAIMerge, a tool that brings security testing and AI-generated guidance directly into GitHub code reviews. It scans both the main application and the version proposed in a pull request, highlighting newly introduced, resolved, and existing security issues. An AI language model uses the findings and proposed code changes to generate concise explanations and suggested fixes. We evaluated SafeAIMerge through a survey of 46 industry practitioners and a controlled study with 12 developers. In the controlled study, 11 of 12 developers fixed at least one vulnerability using SafeAIMerge, compared with 1 of 12 using the standard ZAP workflow. Participants also reported substantially lower workload, and all 12 preferred SafeAIMerge.
Featured Image
Photo by Towfiqu barbhuiya on Unsplash
Why is it important?
Finding a security weakness is only the first step: developers must understand it and know how to address it. Complex reports and disconnected tools can make that process difficult, particularly for developers without specialist security experience. This research shows how clear explanations, practical fix suggestions, and feedback delivered within code review can help developers turn security findings into action. Both study conditions contained the same underlying security findings, highlighting the importance of how results are communicated and integrated into everyday work. The findings provide promising evidence for designing security tools around developer needs, alongside their technical detection capabilities.
Perspectives
Research has shown AI-generated summaries could make security alerts easier to understand. With SafeAIMerge, we took the next step: bringing those summaries, code context, and suggested fixes into developers’ existing workflows. We wanted to examine not just whether developers preferred the feedback, but whether they could use it to address vulnerabilities. The controlled study produced encouraging results, while also reinforcing the need for larger evaluations in real development environments. We view AI-generated guidance as support for developer judgment, not a substitute for reviewing and validating security fixes.
Arpit Thool
Virginia Polytechnic Institute and State University
Read the Original
This page is a summary of: SafeAIMerge: A Tool for Integrating DAST and LLM-Generated Security Feedback into GitHub Actions Workflows, June 2026, ACM (Association for Computing Machinery),
DOI: 10.1145/3805773.3806003.
You can read the full text:
Resources
Contributors
The following have contributed to this page







